Show filters
210 Total Results
Displaying 21-30 of 210
Sort by:
Attacker Value
Unknown
CVE-2023-5840
Disclosure Date: October 29, 2023 (last updated November 08, 2023)
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
0
Attacker Value
Unknown
CVE-2023-5838
Disclosure Date: October 29, 2023 (last updated November 09, 2023)
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.
0
Attacker Value
Unknown
CVE-2023-45653
Disclosure Date: October 16, 2023 (last updated October 20, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Video Playlist For YouTube plugin <= 6.0 versions.
0
Attacker Value
Unknown
CVE-2023-26537
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <= 1.0.2 versions.
0
Attacker Value
Unknown
CVE-2019-25147
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping in the track_link function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-31741
Disclosure Date: May 23, 2023 (last updated October 08, 2023)
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.
0
Attacker Value
Unknown
CVE-2023-31740
Disclosure Date: May 23, 2023 (last updated October 08, 2023)
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and WL_atten_ctl in the apply.cgi interface, thereby gaining shell privileges.
0
Attacker Value
Unknown
CVE-2023-31742
Disclosure Date: May 22, 2023 (last updated October 08, 2023)
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.
0
Attacker Value
Unknown
CVE-2023-22689
Disclosure Date: May 20, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions.
0
Attacker Value
Unknown
CVE-2023-31631
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
An issue in the sqlo_preds_contradiction component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
0